15 min read
Axios npm compromise: XOR dropper to cross-platform RAT
Axios 1.14.1 supply chain attack torn apart. XOR dropper deobfuscated, macOS Mach-O decompiled, Windows PowerShell RAT reversed, C2 protocol mapped.
Anyone can publish to npm, and a package your build already trusts can turn hostile in a single release. Most of it is the same handful of tricks: run on install, read the environment, post it somewhere. Thanks to Artifactly for the feed, and to Permiso, we appreciate you.
Updated 05:00 UTC
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.